Impact
An integer overflow or wraparound condition exists in yoyofr modizer, allowing an attacker to supply numeric input that causes arithmetic operations to wrap incorrectly. The resulting improper value can lead to buffer overflows or corrupted memory that may be exploited to execute arbitrary code or gain unauthorized system access. The flaw is classified as CWE‑190 and the CVSS score of 7.8 indicates a high likelihood of significant harm if exploited.
Affected Systems
The vulnerability affects installations of yoyofr modizer that are versions earlier than 4.1.1. The tool is used in environments where the modizer package is rendered by yoyofr.
Risk and Exploitability
The CVSS score of 7.8 denotes a severe impact, while the EPSS of less than 1% indicates a low probability of exploitation at the time of assessment. It is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet. Based on the description, it is inferred that an attacker could trigger the overflow by crafting specially crafted input, potentially via a web interface or API that passes numeric values to the modizer module. The attack vector is likely remote if the module is exposed to external users.
OpenCVE Enrichment